CUSTOMER STORY · TRUFFLEHOG ENTERPRISE

TextNow catches exposed credentials before landing in production

TextNow needed a consistent way to find exposed credentials across the systems its teams use every day. TruffleHog Enterprise replaced ad hoc scanning with broader coverage, credential verification, and a faster path from detection to remediation.

“The number of things that got dredged up that we hadn’t seen or touched in 4+ years I’ve been here was really surprising.”

Andrew Cotton, Head of Security, Compliance, and IT, TextNow

CUSTOMER SNAPSHOT

INDUSTRY

Telecommunications

DEVELOPERS

~100

TEAM

Security and IT

USE CASE

Secrets detection and remediation

HOW TEXTNOW USES TRUFFLEHOG ENTERPRISE

Finds secrets beyond source code

Scans source code, Jira, and Confluence, including attachments and personal spaces.

Prioritizes active credentials

Verification helps the team decide which exposures require immediate response.

Confirms remediation

Security can revalidate a credential after rotation before closing the incident.

01 · THE CHALLENGE

Periodic scanning left gaps in visibility

Before TruffleHog Enterprise, TextNow used periodic secrets scans as part of its security process. But without continuous coverage, the team did not always have a complete view of credentials exposed across historical code and collaboration systems.

The potential exposure surface also extended beyond source code. Credentials could appear in ticket attachments, build files, old documentation, and personal workspaces, making broader visibility difficult to achieve through periodic scanning alone.

02 · WHAT CHANGED

The proof of concept showed what the team was missing

After connecting Jira, TruffleHog Enterprise surfaced a credential inside a build file package in a ZIP attachment. In Confluence, it identified credentials in historical documentation and personal spaces that were not part of the team’s normal review process.

Credential verification made that broader coverage operationally useful. TextNow can use whether a credential is live to help decide when an exposure requires an immediate response and when it can be handled during normal working hours.

“If it’s not an active key, we don’t need to wake someone up in the middle of the night. If it’s an active key, yes, let’s wake somebody up so we can start some response to it.”

Andrew Cotton, Head of Security, Compliance, and IT, TextNow

03 · IN PRACTICE

An AI-built internal app exposed multiple credentials

24 hours

from commit to rotation — before the app reached production

A technical program manager used AI to build an internal application for tracking projects. The application needed access to several internal services, and its configuration included multiple credentials that were committed alongside the project.

When the application was committed to source control, TruffleHog Enterprise detected active credentials associated with several services. The security team worked with the application owner to rotate the affected credentials and resolved the issue within roughly 24 hours, before the application reached production or other engineers began using it.

“The day it got uploaded to our source code repository, we had the ticket and it was resolved within like 24 hours. Before it got to production, before any other engineers were touching it, and before anybody even started accessing the app.”

Andrew Cotton, Head of Security, Compliance, and IT, TextNow

04 · OUTCOME

A consistent safety net for credential exposure

TruffleHog Enterprise has also surfaced legacy API keys issued by vendors whose relationships with TextNow had ended years earlier but whose credentials were still active on the provider side. TextNow notified the affected vendors, and in at least two cases those vendors said they had been investigating anomalous activity involving keys that had not been properly terminated.

For TextNow, the broader change is that secrets detection no longer depends on periodic scanning alone. The team has wider visibility into where credentials can leak, a reliable signal for prioritizing active exposures, and a way to revalidate credentials during remediation.

“That’s one thing I don’t have to worry about right now.”

Andrew Cotton, Head of Security, Compliance, and IT, TextNow

KEY TAKEAWAYS

Three shifts for TextNow’s security team

Broader secrets visibility

Found credentials in places the team was not actively checking, including Jira attachments and historic Confluence content.

Urgent alerts only when warranted

Credential verification helps the team reserve immediate response for active exposures.

Faster remediation confidence

On-demand reverification lets security confirm that a credential was actually rotated before closing the incident.

Find exposed credentials before they become a bigger problem.

See how TruffleHog Enterprise helps security teams discover and verify exposed credentials across the systems their teams use every day.

infra